Open-source atomic malware analysis

Analyze another

20ff36aec4494f87dc9515358faef0967fda06e89fe6568cbc31ffcafb895d72

PE
Verdict: HOSTILE
AI Unsigned WebSocket backdoor with registry mutation
Mal-ecule
K(Li)O₂(C₂Dy)H₇(Cm₇Cr₁₀DbMgOs₃Po₆Ti)Md₂(Bi₃)
Size 5.1 MB download
First seen 2 days ago
Analyzed 1 day ago
Ecosystem windows
Source abuse.ch
Also detected by 2 sources
Unsigned WebSocket agent with registry mutation and child-process tasking: file:0x3a4040
Unsigned Windows native WebSocket agent with child-process tasking: file:0x3a4108
file pe
0x1fed 204d756c7469706c69636174696f6e20 Multiplication
0x1ffd 666f72207838365f36342c2043525950 for x86_64, CRYP
0x200d 544f47414d53206279203c6874747073 TOGAMS by <https
0x201d 3a2f2f6769746875622e636f6d2f646f ://github.com/do
0x202d 742d61736d3e00909090909090909090 t-asm>..........
0x203d 9090905657535541544155415641579c ...VWSUATAUAVAW.
0x204d 4883ec40498b H..@I.
0x3a3ff8 0000000000000000000100002c010000 ............,...
0x3a4008 ffffffff000000000000000000000000 ................
0x3a4018 00000000000000000000000000000000 ................
0x3a4028 00000000000000000000000000000000 ................
0x3a4038 00000000000000000000000000000000 ................Unsigned WebSocket agent with registry mutation and child-process tasking
0x3a4048 00000000000000000000000000000000 ................
0x3a4058 00000000000000000000000000000000 ................
0x3a4068 00000000000000000000000000000000 ................
0x3a4078 00000000000000000000000000000000 ................
0x3a4088 00000000000000000101010101010101 ................
0x3a4098 01010101010101010909090909090909 ................
0x3a40a8 09090909090909090707070707070707 ................
0x3a40b8 07070707070707070707070707070707 ................
0x3a40c8 07070707070707070808020202020202 ................
0x3a40d8 02020202020202020202020202020202 ................
0x3a40e8 02020202020202020a03030303030303 ................
0x3a40f8 03030303030403030b06060605080808 ................
0x3a4108 08080808080808080001020305080701 ................Unsigned Windows native WebSocket agent with child-process tasking
0x3a4118 01010406010101010101010101010101 ................
0x3a4128 01010101010101010100010101010100 ................
0x3a4138 01000101010101010102010101010102 ................
0x3a4148 01020101010101010101010101010102 ................
0x3a4158 01010101010101010102010101010101 ................
0x3a4168 01020101010101010101010101010103 ................
0x3a4178 01030101010101010103010101010103 ................
0x3a4188 01030101010101010103010101010101 ................
0x3a4198 010101010101010180c14b4001000000 ..........K@....
0x3a41a8 401411400100000000aa104001000000 @..@.......@....
0x3a41b8 50c24b40010000001061114001000000 P.K@.....a.@....
0x3a41c8 00aa1040010000003a20000000000000 ...@....: ......
0x3a41d8 d8c24b40010000001061114001000000 ..K@.....a.@....
0x3a41e8 00aa10400100000068c34b4001000000 ...@....h.K@....
0x3a41f8 e06011400100000070ad114001000000 .`.@....p..@....
0x3a4208 c0ac1140010000005083114001000000 ...@....P..@....
0x3a4218 40a811400100000060a8114001000000 @..@....`..@....Modify memory page protection
0x3a4228 696f73747265616d0000000000000000 iostream........
0x3a4238 696f73747265616d2073747265616d20 iostream stream
0x3a4248 6572726f7200000066616c7365000000 error...false...
0x3a4258 7472756500000000e8c34b4001000000 true......K@....
0x3a4268 e05f1140010000008016114001000000 ._.@.......@....
0x3a4278 9014114001000000b0a5114001000000 ...@.......@....
0x3a4288 a0a511400100000010a6114001000000 ...@.......@....
0x3a4298 00a6114001000000b0a6114001000000 ...@.......@....
0x3a42a8 c0171140010000008096114001000000 ...@.......@....
0x3a42b8 c01711400100000088c44b4001000000 ...@......K@....
0x3a42c8 106111400100000000aa104001000000 .a.@.......@....
0x3a42d8 d0bb4b40010000006061114001000000 ..K@....`a.@....
0x3a42e8 696f735f626173653a3a626164626974 ios_base::badbit
0x3a4968 000000003a000000486f73743a200000 ....:...Host: ..
0x3a4978 557067726164653a20776562736f636b Upgrade: websockUnsigned WebSocket agent with registry mutation and child-process tasking
0x3a4988 65740d0a00000000436f6e6e65637469 et......ConnectiUnsigned Windows native WebSocket agent with child-process tasking
0x3a4998 6f6e3a20557067726164650d0a000000 on: Upgrade.....
0x3a49a8 5365632d576562536f636b65742d5665 Sec-WebSocket-Ve
0x3a49b8 7273696f6e3a2031330d0a0000000000 rsion: 13.......
0x3a49c8 5365632d576562536f636b65742d4b65 Sec-WebSocket-Ke
0x3a49d8 793a200000000000557365722d416765 y: .....User-Age
0x3a49e8 6e74000000000000557365722d416765 nt......User-Age
0x3a49f8 6e743a20000000004f726967696e0000 nt: ....Origin..
0x3a4a08 3a2f2f00000000004f726967696e3a20 ://.....Origin:
0x3a4a18 000000 ...
0x4e23b4 00005700575341536f636b6574410000 ..W.WSASocketA..
0x4e23c4 5753325f33322e646c6c000059004365 WS2_32.dll..Y.CeUnsigned Windows native WebSocket agent with child-process tasking
0x4e23d4 72744f70656e53746f72650012004365 rtOpenStore...Ce
0x4e23e4 7274436c6f736553746f rtCloseSto
0x4e28ea 57696e646f7753746174696f6e00e601 WindowStation...
0x4e28fa 476574557365724f626a656374496e66 GetUserObjectInf
0x4e290a 6f726d6174696f6e570099024d657373 ormationW...Mess
0x4e291a 616765426f7857005553455233322e64 ageBoxW.USER32.d
0x4e292a 6c6c0000a40252656753657456616c75 ll....RegSetValu
0x4e293a 6545784100005f025265674372656174 eExA.._.RegCreatUnsigned WebSocket agent with registry mutation and child-process tasking
0x4e294a 654b6579457841005702526567436c6f eKeyExA.W.RegClo
0x4e295a 73654b657900ed004465726567697374 seKey...Deregist
0x4e296a 65724576656e74 erEvent

Well-known

Objectives

Micro-behaviors

Metadata

20 of 38 traits shown

Identity

SHA-256 20ff36aec4494f87dc9515358faef0967fda06e89fe6568cbc31ffcafb895d72
Filename file
Package 20ff36aec4494f87dc9515358faef0967fda06e89fe6568cbc31ffcafb895d72

Origin

Source harvest
Feed malwarebazaar
Ecosystem windows
Domain abuse.ch

Timeline

First seen 22 Jul 2026 17:11 UTC
First analyzed 23 Jul 2026 04:11 UTC
Last analyzed 23 Jul 2026 04:52 UTC
Last updated 23 Jul 2026 04:52 UTC

Labeling

Label bad
Label source harvest
Traits version 2678d